SAP NetWeaver ABAP Server是德国思爱普(SAP)公司的一个用作 SAP 产品的 Web 应用程序服务器。 SAP NetWeaver ABAP Server存在跨站脚本漏洞,该漏洞源于未对用户控制的输入进行充分编码,从而导致跨站脚本 (XSS) 漏洞。低权限的攻击者成功利用该漏洞后,对应用程序数据的机密性造成的影响有限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP NetWeaver ABAP Application Server and ABAP Platform | SAP_BASIS 700 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-21737 | 8.4 HIGH | Code Injection vulnerability in SAP Application Interface Framework (File Adapter) |
| CVE-2024-22125 | 7.4 HIGH | Information Disclosure vulnerability in Microsoft Edge browser extension (SAP GUI connecto |
| CVE-2024-21735 | 7.3 HIGH | Improper Authorization check in SAP LT Replication Server |
| CVE-2024-21736 | 6.4 MEDIUM | Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management) |
| CVE-2024-22124 | 4.1 MEDIUM | Information Disclosure vulnerability in SAP NetWeaver Internet Communication Manager |
| CVE-2024-21734 | 3.7 LOW | URL Redirection vulnerability in SAP Marketing (Contacts App) |
No comments yet